Group 7: Automated Environment

30 original descriptive cases. Descriptive mix: 9 at 3 marks, 14 at 5 marks, 7 at 10 marks.

Original practice, not ICAI questions, official suggested answers or an official examiner scheme. Equivalent correct work is credited within the stated caps. Public practice availability is not full official question-bank completion.

AUD-G07-D001 · 3 marks

An ERP is not a guarantee of an easy audit Aspen Goods moves from standalone accounting software to an integrated ERP linking sales, inventory and finance. Management says faster processing guarantees fewer audit risks and simpler work. Required: Explain automation's benefits, complexity and the guarantee limit. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Automation can increase speed, volume capacity and integration.The linked systems may reduce manual processing and supply timely information.
1Greater automation/integration can make the audit environment more complex.Understand interfaces and dependencies rather than assume an ERP is easier than standalone software.
1Benefits do not guarantee correct data or effective controls.Assess actual IT risks/controls and evidence; faster processing can still process inaccurate data or unauthorised changes.

Non-credit errors

  • No ERPmeanszerorisk guarantee.
Official ICAI concept source

AUD-G07-D002 · 5 marks

Understand the environment before naming its risks Bay Logistics uses a cloud billing application, local inventory software and a new interface version. Maintenance is outsourced; an administrator holds privileged access. The file only names the billing brand. Required: Give five distinct areas of applied IT understanding to add. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Identify systems and their purposes.Record billing/inventory applications and their financial/nonfinancial roles, not just a brand.
1Understand location and architecture.Distinguish cloud/local arrangements and relevant operation/dependency information.
1Understand versions and interfaces.Investigate the new interface version, data flow and changed functions/risks.
1Understand in-house/packaged arrangements and outsourced activities.Identify maintenance responsibilities and how outsourced work affects the actual systems.
1Identify key people, dependencies, relevant risks/controls and document the understanding.Record administrator responsibilities/access and source evidence; naming staff is not proving controls effective.

Non-credit errors

  • No five brandnamesinplaceofunderstanding.
Official ICAI concept source

AUD-G07-D003 · 5 marks

Three control layers in one payment process Cove Manufacturing restricts system changes and privileged access centrally. Its payment application rejects incomplete bank fields. A manager manually reviews a system-produced exception report, but source data reliability has not been assessed. Required: Classify the three layers, explain their relationship and identify the report-review limit. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Central program-change/access controls are general IT controls.They support multiple applications/data integrity rather than only one payment check.
1The embedded mandatory-field check is an automated application control.It operates within the payment process to address relevant input completeness.
1Manual review using system information is IT-dependent.The manager's report review remains manual but depends on IT-produced data.
1General and application controls are interrelated.Relevant effective supporting controls matter to application and IT-dependent reliability; labels alone do not establish operation.
1Review quality cannot cure unsupported source information automatically.Assess report/source completeness and accuracy and actual review evidence before relying on the manual review.

Non-credit errors

  • No manualreviewmeansindependentofIT rule.
Official ICAI concept source

AUD-G07-D004 · 3 marks

A back-end edit bypasses the visible screen Delta Med's user-entry screen validates amounts, but a privileged operator can edit database values directly. The audit team says the entry check protects every possible data change. Required: Identify the two relevant risk routes and the implication. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Direct back-end data changes are an IT risk.The entry screen may not cover edits made directly in stored data.
1Excessive/privileged or unauthorised access is a distinct concern.Investigate actual rights and change capability, not only the ordinary user interface.
1Assess relevant access/change controls and resulting data evidence.Do not assume the application validation covers all routes or assert a misstatement already occurred; determine appropriate work.

Non-credit errors

  • No validationcoversallbackendchanges rule.
Official ICAI concept source

AUD-G07-D005 · 10 marks

Build a six-risk IT response map Estuary Foods' ERP review identifies: A. Incorrect customer prices are imported even though multiplication is accurate. B. A superuser can edit ledger data directly without an independent review. C. Developers release price-rule changes without approval or testing. D. A required tax-rule update has not been implemented; no current law conclusion is supplied. E. The same person creates suppliers, approves payments and records them. F. Backup jobs fail and restored data have not been checked. No actual loss, fraud or reporting opinion conclusion is supplied. Required: (a) Map each issue to a distinct IT risk and a relevant control/evidence direction. (6 marks) (b) Explain two implications for data/control reliance. (2 marks) (c) State reporting and evidence boundaries. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1A: processing inaccurate input data despite correct calculations.Investigate import/source price accuracy and relevant input/processing controls; multiplication alone does not validate prices.
1B: privileged access and direct data-change risk.Inspect actual permissions/change records and relevant access/review controls; do not infer all edits were improper.
1C: unauthorised/untested program changes.Investigate approval, tracking and testing of changes through relevant general controls.
1D: failure to make necessary system changes.Understand the required update and actual configuration/changes; verify relevant legal facts separately before any tax-compliance conclusion.
1E: inadequate segregation of duties.Assess incompatible access/roles and actual authorisation/recording controls rather than treat the software as automatically segregated.
1F: loss of data/operations-recovery concern.Inspect backup jobs, retention and available restoration evidence; do not invent successful recovery.
1Unmitigated risks can undermine reliability of system information.Determine completeness/accuracy evidence and appropriate additional or alternative substantive work.
1They can undermine application/system-calculation reliance.Evaluate relevant general controls and application/dependent checks, not unconditional reliance from ERP status.
1Report implications depend on applicable duties and evidence.Some circumstances can affect controls reporting, but these indicators do not automatically select an opinion or prove fraud.
1Document actual understanding, tests and unresolved issues.Proposed checks are not performed evidence; choose procedures by risk, complexity and relevant assertions.

Non-credit errors

  • No sixgenericpasswordanswers.
  • No inventedtaxlaworautomaticreport.
Official ICAI concept source

AUD-G07-D006 · 5 marks

Four general-control objectives are different Fjord Services has failed batch jobs/backups, untracked program changes, uncontrolled access and a new system implemented without testing. A trainee calls every issue only an application input check. Required: Map the four general-control areas and explain their shared relationship to reporting. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Data-centre/network operations controls address production processing, jobs and backups/recovery.Investigate job failures and available backup/retention/recovery evidence.
1Program-change controls keep modified systems aligned to reporting objectives.Examine change tracking, approval and testing rather than only current screen output.
1Access controls address authenticated/authorised access to programs/data.Assess actual permissions/security and relevant access evidence.
1Acquisition/development/maintenance controls address development/configuration/implementation.Investigate project analysis, testing and quality checks for the new system.
1General controls support many applications and effective application functioning.These are broader supporting controls, not four names for one embedded input validation; assess actual effectiveness.

Non-credit errors

  • No allfouronlymandatoryfieldchecks.
Official ICAI concept source

AUD-G07-D007 · 3 marks

A manual exception judgement can still matter Grove Designs has rare complex transactions requiring discretion beyond its existing automated rules. Management says all manual elements must be removed because automated processes are always suitable. Required: Explain judgement suitability, changing/exception conditions and the reliability limit. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Manual elements may suit unusual/nonrecurring transactions needing judgement.The rare complex transactions are not automatically best addressed by fixed rules alone.
1Manual work may address unpredictable errors or changed conditions beyond automated scope.Use appropriate discretion/monitoring for exceptions rather than pretend every case was anticipated.
1Manual consistency cannot be assumed and needs relevant controls/evidence.Human error/bypass/override risks remain; neither manual nor automated labels guarantee suitability or operation.

Non-credit errors

  • No allmanualmustberemoved rule.
Official ICAI concept source

AUD-G07-D008 · 5 marks

A walkthrough is a plan, not all-period proof Harbour Supplies' auditor proposes an end-to-end transaction walkthrough, observation under different user scenarios and inspection of application configuration. The team then calls all automated controls effective for the full year, without considering general controls. Required: Explain the three understanding/testing actions, the role of corroborated inquiry and the control-reliance limit. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Walk through actual end-to-end processing using combined inquiry/observation/inspection.Trace relevant stages/dependencies rather than only ask whether the system works.
1Observe user processing under relevant different scenarios.Investigate actual normal/exception behaviour; one observed path does not cover all scenarios.
1Inspect application configuration.Read relevant actual settings/rules, not assume screenshots establish unchanged configuration all year.
1Inquiry alone is insufficient and combinations require judgement.Corroborate responses with relevant tests and document scope/judgement; no universal single method is best for every objective.
1Relevant general-controls assessment/testing and evidence support reliance.Automation consistency is qualified; determine whether additional or alternative work is needed, not all-year effectiveness from a proposed walkthrough.

Non-credit errors

  • No plannedwalkthroughalreadycompletedoruniversalproof.
Official ICAI concept source

AUD-G07-D009 · 5 marks

Analytics can support work without proving fraud Inlet Rentals uses an audit tool to reconcile extract counts, select transactions, recompute a balance and flag unusual journals. The junior says every flagged journal is fraud and the tool eliminates data validation. Required: Explain four distinct uses and the evidence/conclusion boundary. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1CAATs can check completeness of data/populations used in tests.Reconcile extracts to relevant source information; the tool's presence is not itself a completed completeness check.
1They can select samples using appropriate methods.Selection tools help implement the design but do not automatically establish sample adequacy.
1They can reconstruct/recompute balances or mathematical calculations.Evaluate inputs/rules and reconcile outputs rather than treat a computed number as all-assertion proof.
1They can analyse journals and support investigation/control-deficiency evaluation.Unusual journals can be candidates for further work, not automatically fraud.
1Meaningful output requires relevant reliable information and evaluated evidence.Validate appropriate input scope and investigate flags; technology does not remove auditor judgement or determine the opinion.

Non-credit errors

  • No flagmeansprovedfraud.
Official ICAI concept source

AUD-G07-D010 · 10 marks

A report-driven control depends on its source Juniper Shipping's manager manually reviews an ERP payment exception report. The report omits one interface batch, relies on a changed query never tested and can be edited by a privileged user. The application rejects missing supplier codes for normal input, but this does not cover the omitted batch. The auditor has only management's statement that the review is done monthly. Required: (a) Classify the manual report review, embedded validation and supporting controls, applying the distinctions. (3 marks) (b) Analyse the three report/source weaknesses and propose relevant evidence work. (3 marks) (c) Explain review-operation evidence and alternative audit work. (2 marks) (d) State two scope/conclusion boundaries. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1Manual review of IT information is IT-dependent.The manager's review depends on the report/source, not merely personal skill.
1Embedded mandatory supplier-code validation is an application control.It covers its actual normal-input scope; it does not automatically restore an omitted interface.
1Relevant query-change/access/operations controls are supporting general-control areas.Their actual effectiveness affects report/application/dependent reliability, not merely their category labels.
1Omitted batch is a completeness concern.Reconcile relevant batch/source totals and trace interface processing before relying on the report.
1Untested query change is a program/report-processing concern.Inspect change/test evidence and independently validate relevant report logic/output; do not invent successful tests.
1Editable output creates access/data-integrity concerns.Inspect actual privileges/change evidence and relevant restrictions or review controls rather than accept ordinary-screen validation as protection.
1Corroborate actual monthly review operation beyond inquiry.Inspect review/follow-up evidence and observe/reperform relevant elements as appropriate; management statement alone is not all-period proof.
1If supporting controls are absent/ineffective, assess risks and plan appropriate alternatives.Obtain completeness/accuracy evidence and substantive/other work needed for system information rather than automatic reliance.
1No actual misstatement/fraud amount is established by the weaknesses.Investigate evidence without converting every omission/edit capability into a loss.
1No automatic opinion or statutory duty follows from this case.Reporting depends on applicable requirements and evaluated facts; document actual work, scope and unresolved gaps.

Non-credit errors

  • No manualreviewfixesunreliablesource automatically.
  • No inputvalidationcoversomittedinterfaces.
Official ICAI concept source

AUD-G07-D011 · 3 marks

A sequence gap is not a sale by itself An order application's sequence check identifies missing number 418. The team wants to record it as an omitted sale without checking cancelled orders or how numbers are assigned. Required: Explain the control type, follow-up and conclusion limit. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Sequence-number checking is an embedded application-control example.Its actual design and numbering scope determine what a gap means.
1Investigate the gap using relevant underlying records and processing explanations.Determine whether 418 was cancelled, unused or related to a transaction omitted from relevant records; corroborate explanations.
1An exception is not itself an established omitted sale.Do not invent a revenue adjustment or fraud conclusion without evidence of the transaction and its accounting treatment.

Non-credit errors

  • No gap automatically equals omitted revenue.
Official ICAI concept source

AUD-G07-D012 · 5 marks

An approved limit can be poorly configured A purchase application blocks approvals above each user's limit. The senior purchaser is incorrectly configured with an unlimited allowance; no review of settings is available. A valid supplier code is mandatory. Management says these two checks prove all purchases are authorised. Required: Analyse the two checks, the setting weakness, supporting control work and the reliance limit. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1The user-limit check is an application control over its designed approval scope.Inspect the actual limit rule and its operation rather than rely on the feature description.
1The mandatory supplier field is a different application check.A present valid code does not establish that the purchaser had proper approval authority for every purchase.
1Incorrect unlimited configuration undermines the intended limit.Compare the configured permission with the actual authorised limit and investigate relevant affected transactions.
1Relevant configuration/change and access controls support the application.Inspect approval/testing of settings and actual ability to change limits, with evidence appropriate to the period.
1Assess actual operation and alternative work before reliance.Two named checks do not prove all-transaction authorisation; document scope, tests and unresolved weaknesses.

Non-credit errors

  • No mandatory code proves every purchase authorised.
Official ICAI concept source

AUD-G07-D013 · 5 marks

A release ticket without a tested release A pricing program was changed in June. A ticket approves the request, but the installed version differs from the tested version. No evidence shows what happened between testing and installation. Required: Explain the objective and four applied evidence steps or limits. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Program-change controls aim to keep modified systems meeting financial-reporting objectives.Approval of a request is only one part of controlling the actual change.
1Trace the request through recording, tracking and actual implementation.Identify which change/version was installed and who carried it out.
1Compare test evidence with the installed version.Determine whether the evidence supports the actual pricing logic, not merely an earlier build.
1Inspect relevant implementation authorisation and access evidence.Investigate the unexplained version difference and ability to substitute a release.
1Assess output risks and appropriate further work.Validate relevant pricing processing/output and determine reliance; do not claim the installed version passed tests that covered another version.

Non-credit errors

  • No approved ticket proves a different installed version tested.
Official ICAI concept source

AUD-G07-D014 · 5 marks

Green backup status, unproven restoration A monthly dashboard says all backups succeeded. The retained backup excludes the transaction database, and the recovery exercise only opened the application's login screen. Management calls this proof that all financial data can be restored. Required: Explain the control area and four applied checks or conclusions. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Data-centre/network operations controls include backup retention and recovery from failures.The objective concerns production processing and financial-reporting information, not just a green dashboard.
1Check what data the backup actually contains.Compare backup scope with the relevant transaction database and necessary system dependencies.
1Inspect scheduling, execution, retention and exception evidence.A dashboard label needs corroboration of relevant jobs and usable retained copies.
1Assess what the recovery exercise actually demonstrated.Opening a login screen does not establish restoration of complete and accurate financial transactions.
1Evaluate the gap and appropriate alternative evidence/work.Investigate data-loss/reliability risks without inventing a successful recovery or asserting an actual loss occurred.

Non-credit errors

  • No login screen proves complete financial-data restoration.
Official ICAI concept source

AUD-G07-D015 · 10 marks

Validate the population before trusting the tool An audit extract for the financial year contains only the online sales channel. The ledger also includes store sales. The export job silently skips failed rows, duplicates rows on retries and maps credit-note amounts as positive. A trainee's tool reports that the extracted file's row count agrees with its own imported count, so the trainee proposes full reliance on the result. No reconciliation to source records has been done. Required: (a) Analyse four distinct extract weaknesses and relevant evidence work. (4 marks) (b) Explain why the tool's count agreement is insufficient and propose two source/output validations. (3 marks) (c) Explain the effect on audit use and two conclusion boundaries. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Channel coverage is incomplete for a combined-sales objective.Identify relevant store and online source populations; reconcile coverage before calling the export the full population.
1Skipped failed rows create an omission risk.Inspect export errors and reconcile failed records with relevant source information and corrected extracts.
1Retried duplicate rows can distort counts and amounts.Investigate transaction identifiers/retry records and validate legitimate duplicates versus repeated exports.
1Credit-note sign mapping can distort the monetary output.Check mapping against actual source transactions and relevant calculation logic; do not simply total the imported signs.
1Internal file/import agreement only shows agreement within the supplied extract.It cannot detect source transactions never exported or prove that values were mapped correctly.
1Reconcile relevant source totals and scope with the proposed population.Use appropriate independent source information, investigate differences and document the period/channel coverage.
1Trace selected source records through export and recompute relevant output.Test inclusion and mapping in appropriate directions, including failures, retries and credit notes; proposed tests are not completed evidence.
1CAAT output is only useful for its valid population and rules.Resolve weaknesses or use appropriate alternative procedures before relying on the analysis for the intended audit purpose.
1Whole-extract analysis is not whole-entity or all-assertion proof.Do not claim every sale or every assertion was tested merely because all imported rows were processed.
1These facts do not quantify an actual misstatement or prove fraud.Investigate evaluated evidence and retain scope limitations rather than invent adjustments or an opinion.

Non-credit errors

  • No self-reconciled file count proves complete source population.
  • No imported-row coverage equals all-assertion assurance.
Official ICAI concept source

AUD-G07-D016 · 3 marks

Outsourcing does not remove the IT dependency A payroll provider maintains the software remotely. The entity's audit file says only "outsourced, therefore no IT understanding needed". The provider changed the version and the entity receives a payroll interface file. Required: Explain three applied understanding points. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Understand outsourced maintenance/support and relevant responsibilities.Outsourcing is a feature to investigate, not a reason to omit the entity's IT understanding.
1Understand the actual version and functions/risks affected.Document the relevant change rather than assume an earlier version description remains current.
1Understand the interface and relevant dependencies/risks/controls.Trace how payroll information reaches the entity's records and document source-grounded understanding; no service-auditor-report conclusion is supplied.

Non-credit errors

  • No outsourcing eliminates all entity IT work.
Official ICAI concept source

AUD-G07-D017 · 5 marks

A reconstructed trial balance can still miss the opening data A CAAT reconstructs a trial balance from current-year transactions. The original ledger includes opening balances, but the extract excludes them. Debits equal credits in the tool. The trainee calls the entity's closing trial balance proved correct. Required: Explain the legitimate use, missing-data implication, two validations and conclusion limit. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Reconstruction of a trial balance is a recognised CAAT use.It can independently recompute relevant balances from appropriate transaction information.
1Omitted opening balances make the intended closing reconstruction incomplete.Identify the data required by the reconciliation rather than treat current-year movement alone as every closing balance.
1Validate relevant input completeness and accuracy.Reconcile transaction coverage and appropriate opening information to supported source records.
1Check the reconstruction rules and investigate ledger differences.Reperform relevant mappings/calculations and reconcile the resulting balances with the actual trial balance.
1Balanced debits and credits do not establish all balances or assertions correct.Equal totals can coexist with omitted or incorrectly mapped data; no all-assertion conclusion follows.

Non-credit errors

  • No balanced extract proves every closing balance.
Official ICAI concept source

AUD-G07-D018 · 3 marks

A weekend journal is an investigation lead An audit tool flags journals posted on weekends. The trainee declares every flagged item fraudulent and every unflagged item safe. Required: Explain the use and the two conclusion errors. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Journal-entry analysis can identify items for further investigation.Review appropriate source data and investigate relevant flagged entries with corroborating evidence.
1A weekend flag is not proof of fraud.Understand legitimate posting circumstances and evaluate the actual entry and supporting evidence.
1Absence of this flag is not proof that an entry is safe.The rule covers only its defined feature; evaluate scope and other risks rather than treat one filter as a universal detector.

Non-credit errors

  • No flag proves fraud; no absence proves safety.
Official ICAI concept source

AUD-G07-D019 · 5 marks

Digital audit needs a scope explanation An audit team uses AI to map purchase flows and analytics to identify unusual payments. Its plan says technology now chooses the opinion, removes professional judgement and ensures no relevant risk is missed. Required: Explain two legitimate benefits, two evidence/judgement limits and one documentation need. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Digital tools can help understand business processes.The purchase-flow mapping may aid planning when its inputs and output are evaluated.
1Technology can help identify risks and focus attention.Unusual-payment analytics can direct further work, rather than merely add a large volume of flags.
1Useful output depends on relevant data and appropriate scope.Validate the information and what the tool actually analysed; the tool name is not evidence of complete risk coverage.
1Auditors still evaluate evidence and use judgement.Technology supports work from planning to opinion but does not itself authorise the opinion or guarantee no risk was missed.
1Document actual use, tests, scope and unresolved matters.Distinguish planned mapping/analytics from work performed and retain the reasoning behind the chosen procedures.

Non-credit errors

  • No AI chooses an audit opinion or guarantees every risk found.
Official ICAI concept source

AUD-G07-D020 · 10 marks

Choose controls for different transaction patterns A wholesaler has 60,000 recurring invoices with predictable missing-field and limit errors. It also has a one-off complex barter transaction outside its existing automated rules. Routine invoices are manually checked by one employee, with skipped reviews during busy days. The automated exception report used by the supervisor is incomplete. A trainee proposes either automating everything or abandoning all automated controls. Required: (a) Explain suitability for routine invoices and the unusual transaction. (3 marks) (b) Analyse manual-review risks and the report dependency. (3 marks) (c) Propose applied evidence work for the redesigned arrangement. (2 marks) (d) State two reliance/conclusion limits. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1High-volume recurring predictable errors can suit designed automated parameters.Relevant mandatory-field and user-limit checks may address specified invoice risks within their actual scope.
1Manual work may be less suitable for consistently repeating well-defined checks.Busy-day omissions show why consistency cannot be assumed merely because a person is assigned.
1Unusual transactions needing judgement may suit manual discretion.The barter transaction may require an appropriate response outside existing automated rules; do not force every case through an unsuitable rule.
1Manual elements can be bypassed, ignored or overridden and suffer errors.Investigate actual coverage and skipped invoice reviews, not just the employee's job description.
1The supervisor's manual review is IT-dependent.Its reliability depends on the completeness/accuracy of the exception report, not only reviewer competence.
1Relevant general controls support application and IT-dependent controls.Assess access, changes and relevant processing dependencies rather than assume all named checks are effective.
1Test relevant configurations and actual normal/exception processing.Combine inquiry with appropriate observation, inspection or reperformance and document judgement and scope.
1Validate report information and actual manual follow-up.Reconcile coverage and inspect review/exception evidence, including the unusual transaction and busy periods as relevant.
1Redesign proposals are not evidence of operation during the audit period.Assess actual implementation/operation and determine additional or alternative audit work before reliance.
1Neither automate-everything nor abandon-all-automation is justified by labels.Choose by transaction characteristics, risks and evaluated evidence; no automatic fraud, adjustment or opinion conclusion follows.

Non-credit errors

  • No one-size-fits-all method or control reliance from a proposal.
Official ICAI concept source

AUD-G07-D021 · 3 marks

A valid login is not a valid permission A former accounts employee's login remains active and retains supplier-edit rights. Management says password authentication proves the employee remains authorised. Required: Explain authentication, authorisation and the applied check. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Authentication verifies the identity used to access the system.A successful login does not establish a continuing business entitlement.
1Authorisation addresses permitted access to relevant programs/data.Retained supplier-edit rights require assessment against current responsibilities, including the departure.
1Inspect actual access and relevant removal/review evidence.Investigate use and affected changes as appropriate; do not presume every change fraudulent or the account removed because a policy exists.

Non-credit errors

  • No password authentication proves current edit authority.
Official ICAI concept source

AUD-G07-D022 · 5 marks

A complete source is not a complete destination Warehouse dispatch software sends data to billing nightly. The dispatch file includes 240 records. Billing rejects 12 with a changed item-code format, but its dashboard reports only successful imports. No one follows up rejected records. Required: Analyse the interface understanding, exception, dashboard limit, applied control evidence and audit-use implication. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Understand the interface and relevant version/data-flow dependencies.Record the changed code format and how dispatch records reach billing.
1Rejected records create a destination completeness concern.Trace the 12 exceptions and their actual resolution/accounting treatment rather than assume all dispatches became bills.
1The successful-import dashboard is not a reconciliation of all dispatch records.Its stated scope excludes failures and cannot prove completeness merely by showing successful jobs.
1Inspect relevant batch/interface and exception-follow-up controls.Reconcile source, imported and rejected records and inspect actual correction/follow-up evidence.
1Determine reliability and alternative work from evaluated results.No amount of omitted revenue is supplied; investigate actual transactions before any adjustment or reliance decision.

Non-credit errors

  • No success-only dashboard proves all source records processed.
Official ICAI concept source

AUD-G07-D023 · 3 marks

A plausible amount can still be wrong An application rejects invoice amounts above a reasonableness ceiling. An invoice is below the ceiling but uses the wrong quantity. A trainee says a passed check proves accuracy. Required: Explain the check, its limit and relevant follow-up. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1A reasonableness check is an application-control example.It checks a defined parameter rather than every source fact.
1Passing the ceiling does not establish the quantity is correct.A plausible amount can still be calculated from incorrect data.
1Validate relevant source quantity and processing evidence.Investigate this mismatch and the intended control scope rather than declare the check universally useless or sufficient.

Non-credit errors

  • No passing reasonableness rule proves all input accuracy.
Official ICAI concept source

AUD-G07-D024 · 5 marks

A job ran, but only half the batches did An accounting scheduler marks the night's processing complete after one job succeeds. A dependent posting job failed, leaving two approved batches unposted. The file contains no retry or reconciliation evidence. Required: Explain the general-control objective, dependency risk, two evidence directions and the conclusion limit. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Operations controls include scheduling, executing and monitoring batch jobs.Their objective concerns processing that meets financial-reporting needs, not simply one success status.
1Dependent-job failure can undermine processing completeness.Determine how the two approved batches should move into the ledger and whether they were later processed.
1Inspect actual scheduler/job/error and retry evidence.Trace dependencies and failed batches rather than assume a parent status proves every downstream job succeeded.
1Reconcile relevant approved batches with ledger postings.Investigate exceptions and actual follow-up; a reconciliation proposed by the auditor is not an existing effective control.
1Assess further work and actual effects from evidence.Unposted batches are not automatically a quantified loss or fraud, and one issue does not determine the opinion.

Non-credit errors

  • No parent-job success proves downstream completeness.
Official ICAI concept source

AUD-G07-D025 · 10 marks

A new application needs more than a launch announcement A distributor replaces its inventory application. The project skipped design review; sales-unit conversion rules were never tested. The installed configuration differs from the accepted build. Staff receive broad administrator rights to fix launch issues, and the first interface run rejects records. Management asks the auditor to rely on all new controls because the launch was approved. Required: (a) Analyse four implementation/support weaknesses with evidence directions. (4 marks) (b) Explain two effects on control and system-information reliance. (2 marks) (c) Set out two appropriate applied testing responses. (2 marks) (d) State two boundaries. (2 marks)
Show answer and marking
MarksCreditCase application / answer
1Acquisition/development controls include analysis/design and testing/quality assurance.Investigate missing design review and validate relevant unit-conversion rules against source requirements and actual operation.
1A different installed configuration needs change/implementation evidence.Compare the accepted build with actual settings and inspect relevant authorisation/testing of differences.
1Broad administrator rights create excessive/privileged-access concerns.Assess current roles, actual capabilities and relevant change/review evidence; launch pressure does not prove appropriate access.
1Rejected interface records require operations/exception work.Reconcile source/import/rejected populations and inspect actual correction and follow-up.
1General controls support embedded and IT-dependent controls.An approved launch is not proof that relevant application checks or report reviews operate effectively.
1Unmitigated risks can undermine system-information reliability.Determine completeness/accuracy work and suitable alternative procedures before using output for the audit purpose.
1Walk through relevant processing and inspect actual configuration.Include normal and exception paths as appropriate, not only a demonstration of the login screen.
1Corroborate claims using appropriate testing and evaluated output.Use observation, inspection or reperformance with inquiry, selected by risks and required evidence; document actual results.
1Testing scope and period must be explicit.A new-system launch test does not establish operation of the old system or every new control throughout the year.
1Weaknesses are not a predetermined misstatement or opinion.Determine actual effects and applicable reporting requirements rather than inventing loss, fraud or statutory applicability.

Non-credit errors

  • No approved launch proves all controls or data reliable.
Official ICAI concept source

AUD-G07-D026 · 3 marks

The rule no longer covers the transaction A company adds multi-currency orders, but an automated limit rule still compares foreign-currency numbers directly with a domestic-currency limit. Management says last year's successful test is sufficient. Required: Explain necessary change, actual-rule evidence and the reliance limit. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Failure to make necessary system changes is an IT risk.The changed transaction pattern may require a rule response beyond the old design.
1Understand the current configuration and relevant change/test evidence.Inspect how currencies and limits actually interact; separately verify any relevant source rates/rules used in testing.
1Prior successful testing does not prove suitability for changed conditions.Evaluate current design/operation and appropriate alternative work without inventing a currency adjustment or claiming every transaction failed.

Non-credit errors

  • No unchanged-rule reliance despite changed transaction conditions.
Official ICAI concept source

AUD-G07-D027 · 5 marks

An unchanged screenshot is a narrow piece of evidence A December screenshot shows an application check enabled. The administrator could change the check during the year, and change records are not inspected. The trainee states the check operated unchanged from April to March. Required: Explain the screenshot's scope, change/access dependency, period implication, applied work and documentation limit. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1A configuration screenshot supports what it actually shows at that time.It does not itself establish all-year operation or handling of every transaction.
1Relevant change and access controls affect confidence in consistent operation.Investigate who could change the check and actual change authorisation/testing evidence.
1Period coverage is unresolved from a single current setting.Identify relevant versions/settings and operating periods rather than silently extend December evidence to the whole year.
1Obtain appropriate corroborating tests/evidence for the intended reliance.Inspect relevant records and observe/reperform relevant processing as appropriate; plan alternatives where supporting controls are absent or ineffective.
1Document actual test scope, judgement and remaining gaps.Do not label a screenshot as all-period proof or an unperformed inspection as completed work.

Non-credit errors

  • No one-date configuration screenshot proves full-year operation.
Official ICAI concept source

AUD-G07-D028 · 5 marks

Recalculation tests the formula, not every assumption A CAAT recomputes depreciation using supplied asset costs, dates and rates. Its calculations agree with management's file. The team has not assessed whether those supplied values are correct or the rule matches the relevant asset circumstances. Required: Explain the use, three validation needs and the assurance limit. (5 marks)
Show answer and marking
MarksCreditCase application / answer
1Reperformance of mathematical calculations is a CAAT use.Agreement can support the specified computation on the supplied data/rule.
1Validate relevant asset-data completeness and accuracy.Costs and dates must be supported for the intended audit purpose, not accepted solely because the formula runs.
1Assess the supplied rate/rule against relevant supported circumstances.Do not invent a universal rate or treat management's input as independent evidence of appropriateness.
1Inspect actual formula implementation and reconcile output.Test mapping/calculations and investigate relevant differences or omissions; a matching total can hide data/rule weaknesses.
1Computation agreement is not all-assertion proof.It does not by itself establish asset existence, title or every accounting conclusion; those objectives require appropriate evidence outside this narrow calculation.

Non-credit errors

  • No mathematically matching output proves all inputs or assertions.
Official ICAI concept source

AUD-G07-D029 · 10 marks

Use analytics to investigate a control deficiency A payment approval control was disabled for part of the year. A CAAT finds payments above the configured limit during that period. The extract includes only one business unit, uses the current limit instead of historical limits and includes both original and reversed entries. A trainee labels the sum of all flags as fraud loss and says unflagged payments need no attention. Required: (a) Explain the legitimate audit use and three data/rule weaknesses. (4 marks) (b) Propose three distinct applied evidence responses. (3 marks) (c) Explain three conclusion boundaries. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Analytics can help evaluate the impact of control deficiencies.Use relevant payment analysis to direct investigation of the disabled approval control rather than substitute flags for evaluated evidence.
1Single-unit coverage limits the population conclusion.Identify relevant units and data coverage for the intended deficiency assessment.
1Current limits may misclassify historical transactions.Determine relevant effective limits and periods from supported source information.
1Original and reversal records can distort the flagged total.Understand relationships and treatment before calculating affected payment amounts.
1Validate extract scope/completeness and relevant values.Reconcile the intended unit/period population to supported source records and investigate omissions.
1Reperform appropriate historical-limit classification and entry relationships.Check logic with relevant source records rather than assume the current-limit query implements the intended test.
1Inspect actual approval, exception and follow-up evidence for relevant items.Investigate reasons and actual effects and determine further or alternative work as appropriate.
1The sum of flags is not an established fraud loss.A flag may identify an approval issue, data/rule artefact or legitimate transaction requiring further evaluation.
1Unflagged items are not automatically safe.This rule and extract do not cover every risk, transaction or assertion.
1The deficiency does not itself choose the opinion or reporting duty.Evaluate actual scope/results and applicable requirements; proposed follow-up is not work already performed.

Non-credit errors

  • No flag total equals fraud loss; no one-unit analysis equals whole entity.
Official ICAI concept source

AUD-G07-D030 · 10 marks

Migration, legacy records and manual review An entity moves from a local accounting system to a cloud application on 1 January. The migration includes closing balances but omits supporting transaction records needed for the intended audit tests. An interface still sends legacy transactions after cutover, and a manager compares cloud reports to an old spreadsheet populated from those same reports. No independent reconciliation or migration-test results are available. The cloud provider also maintains the application. Required: (a) Identify four applied understanding/data concerns. (4 marks) (b) Explain the review weakness and two evidence directions. (3 marks) (c) Explain period coverage and two conclusion limits. (3 marks)
Show answer and marking
MarksCreditCase application / answer
1Understand the actual old/new architecture and cutover arrangements.Document local-to-cloud locations, systems, versions and responsibilities rather than assume the cloud label reduces complexity.
1Migrated balance coverage differs from supporting transaction coverage.Identify records required by the intended tests and investigate missing transaction information; balances alone are not every audit input.
1Continuing legacy interfaces create data-flow/dependency concerns.Trace post-cutover legacy records into the cloud and investigate relevant omissions/duplicates and processing scope.
1Outsourced maintenance is part of the relevant IT understanding.Identify actual provider/entity responsibilities and relevant access/change dependencies; outsourcing does not erase entity audit work.
1The manual comparison is IT-dependent and uses a circular source.A spreadsheet copied from the same report is not an independent corroboration of report completeness/accuracy.
1Validate relevant migration/interface coverage against supported source information.Inspect actual tests, reconcile relevant old/new records and investigate exceptions; unavailable results must not be described as successful tests.
1Assess relevant configuration/supporting controls and appropriate alternative evidence.Determine how reliable information can be obtained for the intended audit work, including absent transaction records.
1Separate old-system, cutover and new-system periods.Evidence on the January cloud configuration does not automatically cover earlier legacy processing or the whole year.
1Modern hosting does not guarantee controls or data correctness.Choose work by actual risks, complexity and evaluated evidence, not provider reputation or the cloud label.
1No automatic fraud, loss amount or opinion follows.Document gaps and determine actual implications and applicable reporting requirements before conclusions.

Non-credit errors

  • No circular same-source reconciliation establishes independent reliability.
  • No cloud configuration proves legacy-period operation.
Official ICAI concept source